Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
In Microsoft Entra, we group our security recommendations into multiple themes based on the Secure Future Initiative (SFI). This structure allows organizations to logically break up projects into related consumable chunks.
Tip
Some organizations might take these recommendations exactly as written, while others might choose to make modifications based on their own business needs. In our initial release of this guidance, we focus on traditional workforce tenants. These workforce tenants are for your employees, internal business apps, and other organizational resources.
We recommend that all of the following controls be implemented where licenses are available. These patterns and practices help to provide a foundation for other resources built on top of this solution. More controls will be added to this document over time.
Automated assessment
Manually checking this guidance against a tenant's configuration can be time-consuming and error-prone. The Zero Trust Assessment transforms this process with automation to test for these security configuration items and more. Learn more in What is the Zero Trust Assessment?
Protect identities and secrets
Reduce credential-related risk by implementing modern identity standards.
Protect tenants and isolate production systems
Protect networks
Protect your network perimeter.
| Check | Minimum required license |
|---|---|
| Named locations are configured | Microsoft Entra ID P1 |
| Tenant restrictions v2 policy is configured | Microsoft Entra ID P1 |
| Internet Access forwarding profile is enabled | Microsoft Entra Internet Access |
| Global Secure Access web content filtering is enabled and configured | Microsoft Entra Internet Access |
Protect engineering systems
Protect software assets and improve code security.
Monitor and detect cyberthreats
Collect and analyze security logs and triage alerts.
Accelerate response and remediation
Improve security incident response and incident communications.
| Check | Minimum required license |
|---|---|
| Workload Identities are configured with risk-based policies | Microsoft Entra Workload ID |
| Restrict high risk sign-ins | Microsoft Entra ID P2 |
| Restrict access to high risk users | Microsoft Entra ID P2 |